Cybersecurity Lead Associate - Third-Party Risk Management

QXO

• $101K — $172K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in cybersecurity, IT risk management, or vendor risk management
  • Hands-on experience managing a complex Enterprise level program
  • Knowledge of NIST CSF 2.0 and third-party risk frameworks
  • Experience in conducting or reviewing security risk assessments
  • Strong written communication skills for producing risk assessments and executive summaries
  • Experience with Enterprise level platforms used by diverse stakeholders

Responsibilities

  • Own and enhance the TPRM program, managing day-to-day operations and vendor oversight
  • Administer and optimize SecurityScorecard implementation for ongoing risk assessment
  • Conduct risk assessments for new and existing suppliers, focusing on critical data access
  • Collaborate with Procurement and Legal to embed cybersecurity in contracts
  • Track and report on third-party risk posture and remediation to leadership
  • Support M&A due diligence by evaluating cyber risks of potential acquisitions
  • Maintain the Optro TPRM module, ensuring data integrity and user access

Benefits

  • Annual performance bonus
  • 401(k) with employer match
  • Medical, dental, and vision insurance
  • Paid Time Off/Paid Sick Leave, accruing 15 days in the first year
  • Paid training and certifications
  • Legal assistance and identity protection
  • Pet insurance
  • Employee assistance program (EAP)
Full Job Description
As a(n) Cybersecurity Lead Associate - Third-Party Risk Management at QXO, you'll own and mature the Third-Party Risk Management (TPRM) program, including build out and day-to-day administration of our continuous vendor monitoring platform (SecurityScorecard). This role is central to QXO's ability to assess and manage cyber risk introduced through suppliers, technology vendors, and acquired entities as the company continues its acquisition-driven growth strategy.

What you'll do:

  • Independently own the cybersecurity TPRM program: continuous security posture monitoring, supplier due diligence assessments, contract negotiations and redlining, administration of multiple supplier risk management platforms
  • Lead the administration and optimize QXO's SecurityScorecard implementation, including score monitoring, alerting workflows, and vendor outreach for identified issues
  • Conduct security risk assessments of new and existing suppliers, with limited oversight and particular attention to vendors accessing Confidential or Highly Confidential QXO data
  • Serve as the subject matter expert and technical partner with Procurement, Legal, and Business Owners to ensure cybersecurity requirements are embedded in contracts and vendor onboarding
  • Track and report on third-party risk posture, remediation status, and program metrics to Cybersecurity leadership
  • Support due diligence for M&A activity, evaluating the cyber risk profile of acquisition targets and integration plans
  • Administer and maintain the Optro Third-Party Risk Management (TPRM) module, including workflow configuration, user access, and data integrity across compliance and vendor risk assessments.
  • Serve as the primary point of contact for Optro TPRM module support, troubleshooting issues, coordinating platform updates/enhancements, and training end users

What you'll bring:

  • 10+ years of experience in cybersecurity, IT risk management, and/or vendor risk management
  • Hands-on experience owning an Enterprise level program of significant complexity with multiple stakeholder groups
  • Working knowledge of NIST CSF 2.0 and third-party risk frameworks
  • Experience conducting or reviewing security risk assessments
  • Strong written communication skills - this role regularly produces risk assessments and executive-facing summaries
  • Experience administering Enterprise level platforms used by diverse stakeholders

What you'll earn

  • Base pay range: $101,300 - $172,000
  • Annual performance bonus
  • 401(k) with employer match
  • Medical, dental, and vision insurance
  • PTO, company holidays, and parental leave
  • Paid Time Off/Paid Sick Leave: Applicants can expect to accrue 15 days of paid time off during their first year (4.62 hours for every 80 hours worked) and increased accruals after five years of service.
  • Paid training and certifications
  • Legal assistance and identity protection
  • Pet insurance
  • Employee assistance program (EAP)


To comply with Pay Transparency laws, employers must disclose an annual salary range. Actual offers depend on factors such as location, experience, skills, and market data. This position may also offer variable compensation.

Please contact [email protected] if you have any questions related to this job posting.

Salary Range:

USD $101,300.00 - USD $172,000.00 /Yr.

Similar Jobs

More Jobs at QXO

More Information Technology Jobs

Find similar Cybersecurity Lead Associate - Third-Party Risk Management jobs: